Website Tracking Demand Letters: What They Are, and What to Do Now
- Olender Feldman

- Jul 6
- 4 min read
A wave of demand letters related to cookies, pixels, and other tracking devices that are applied prior to visitor consent is reaching businesses of all sizes across the country right now. We want to help equip you to with what you need to know to protect against them, and if one lands on your desk, we wanted to let you know what sits behind it and what you can do to reduce your exposure.
What is happening
A small number of people in California, often acting on their own and in some cases working with a few law firms, visit (or use technology to visit) large numbers of business websites and then send near-identical letters to the companies that run them. The claim leans on the California Invasion of Privacy Act, commonly known as CIPA, an eavesdropping law originally from the 1960s, written for telephone wiretaps, that these senders have repurposed to reach the everyday tracking tools almost every website uses.
The targets are not chosen for doing anything unusual. They are chosen because their sites run the same ordinary tools nearly every site runs: analytics such as Google Analytics, advertising pixels, chat widgets. If you have a website, you almost certainly have some of these, whether you set them up yourself or a website host installed them for you.
The senders send these in high volume, and each one is written to pressure a fast settlement.
On their end it is a numbers game. The statute they cite allows a fixed sum per alleged violation, which is what makes mailing in bulk worth their while. There is no reason to panic, and none of this is specific to working with us or with any one vendor. It is about how websites in general load third-party tools, and whether those tools begin collecting visitor data before anyone has agreed to it. That last point is where you have real control.
The step that matters most
If you do not have a cookie consent banner on your site, this is a good moment to put one in place.
If you already have one, it is worth confirming that it is configured to do its job: to hold cookies, pixels, and similar trackers until a visitor has interacted with the banner and consented to them. Many banners are set up, without anyone intending it, to display a notice while the trackers fire the moment the page loads. That gap is precisely what these letters target. A banner that shows a notice but blocks nothing gives the appearance of protection without the substance of it.
Why this is bigger than the letters
Correcting the banner removes the condition these letters point to. It also reaches a set of obligations that have nothing to do with them, and that apply whether or not a letter ever arrives. Which of these reach you depends on where your visitors are and what your site does.
California's own consumer privacy law, the CCPA as amended by the CPRA, governs website data collection directly. It expects businesses to give notice, to let visitors opt out of the sharing of their data for targeted advertising, and to honor browser-level opt-out signals such as Global Privacy Control. Regulators have already brought enforcement actions over cookie and opt-out failures.
At present, more than twenty other states now have their own comprehensive privacy laws, several of which require honoring universal opt-out signals and offering an opt-out of targeted advertising. If any of your visitors come from the EU or the UK, a stricter rule applies: there, non-essential trackers generally may not fire until the visitor has given prior consent, and that regime carries its own regulator fines. And if your site touches health information, even indirectly through a pixel, a separate layer of law comes into play, including Washington's health-data statute with its private right of action and federal guidance on tracking technologies.
A banner tuned only to the California letters can still leave you out of step with these. The reverse holds as well: a consent setup built correctly for the broader picture addresses those letters as a matter of course.
What doing this properly looks like
Three pieces work together. An accurate, current privacy policy that reflects what your site actually collects and shares. A distinct cookie notice, kept separate from the general privacy policy and reachable from the banner, that describes the categories of trackers, their purposes, and how a visitor exercises choices. And a consent management platform configured, and worded, to match the laws that apply to you rather than a generic default pulled off the shelf.
A note on possible relief
You may have heard that California is weighing whether to narrow this law. A bill that would carve routine commercial website tools out of its reach passed the state Senate but stalled in the Assembly and has been carried over for further consideration. Even if it advances, it is drafted to apply going forward rather than to pending matters, so it offers nothing to a business that receives a letter in the meantime. The practical posture is to fix the site now.
How we can help
Our Privacy, Security & AI team is helping clients review their sites, correct banner configurations, refresh privacy policies, and put a proper cookie notice in place, in alignment with the laws that apply to each business. If you have received a letter, or you would rather get ahead of one, reach out to your OlenderFeldman contact or to SRosenberg@OlenderFeldman.com, who leads our Privacy, Security & AI Practice.
This alert is provided for general informational purposes and does not constitute legal advice or create an attorney-client relationship. It may be considered attorney advertising in some jurisdictions.

Comments